Legal

Privacy notice

How personal information is handled when you contact or engage the firm.

Effective Date: 16 June 2026 · Version 1.3

1. Introduction

Liguanea Advisory Group Limited ("Liguanea Advisory," "the Firm," "we," "our," or "us") is committed to safeguarding the personal information of those who visit our website and communicate with us. This Privacy Notice describes how we collect, use, store, and protect personal information, and the rights available to individuals whose information we hold.

This notice is issued in accordance with the Jamaica Data Protection Act 2020, the supervisory expectations of the Financial Services Commission of Jamaica applicable to service providers engaged with regulated entities, and, where applicable, the European Union General Data Protection Regulation.

2. Who We Are

Liguanea Advisory Group Limited is an advisory firm based in Kingston, Jamaica, providing operations, technology, and strategic advisory services to organizations across the Caribbean region. The Firm acts as a data controller for the personal information it collects through this website and direct communications.

For data protection matters, the responsible contact is:

Liguanea Advisory Group Limited
Attention: Privacy Officer
Email: [email protected]

3. Information We Collect

We collect only the information necessary to respond to inquiries and conduct professional engagements. Specifically:

Information you provide directly: When you submit an inquiry through our contact form, we collect your name, organization, email address, telephone number (if provided), and the content of your message. The email address you submit is checked in real time by an email-verification provider to confirm it is valid and to reduce fraudulent or mistyped submissions; only the address itself is shared for that check.

Technical information collected automatically: When you visit our website, our hosting and content delivery providers may log standard technical information including IP address, browser type, device type, referring page, and pages accessed. This information is collected for security, performance, and abuse-prevention purposes.

Aggregate website analytics: We use a privacy-friendly, cookieless analytics service to understand overall website traffic — such as which pages are viewed and the general regions visitors come from. It does not set cookies, does not track individuals across websites, and does not identify you personally; the information is aggregate only.

Cookies: This website does not use tracking, advertising, or third-party analytics cookies. It sets only strictly necessary cookies — those used by our content delivery network to protect and operate the site, and, within the client area only, a session cookie that keeps you signed in while you are logged in. These cookies are essential to the functioning and security of the site and are not used to profile you or to track your activity across other websites.

Communications: Any subsequent correspondence between you and the Firm, whether by email, telephone, or other means, may be retained as part of our business records.

One-time access codes: When you request access to our intake form or client portal, we generate a one-time access code to verify you. Where you choose to receive that code by text message rather than by email, we collect the mobile telephone number you provide for the purpose of delivering the code.

Information provided by engaged clients through the secure client portal: Clients who have entered into an engagement with the Firm may be invited to use our secure client portal to provide information and exchange documents. Through the portal, and only in the context of an active engagement, we may collect and hold information necessary to conduct that engagement, which may include: the personal particulars of a company's directors, officers, shareholders, and beneficial owners (such as names, contact details, dates of birth, sex, and nationality); government-issued identification and its particulars (passports, driver's licenses, and national or voter's identification, together with the identification type, issuing country, number, and issue and expiry dates); taxpayer registration numbers and other tax identifiers; beneficial-ownership particulars (the extent of a person's ownership or control, any management role, and the date they became a beneficial owner); company incorporation and registration records, including branch addresses, share structure, and business and tax particulars; and other financial and corporate documents. These materials are provided by the client for the purpose of the engagement and are handled in accordance with the security and retention provisions of this notice.

We do not collect special category data, financial account information, or government-issued identification from general visitors to this website or through the contact form. The identity, financial, and corporate documents described above are collected only from engaged clients, through the secure client portal, after an engagement relationship has been established.

4. How We Use Your Information

Personal information is used for the following purposes:

  • To respond to inquiries submitted through our contact form
  • To assess potential engagements and prepare proposals
  • To communicate with prospective and engaged clients
  • To conduct and administer client engagements, including reviewing documents that clients provide through the secure client portal
  • To meet client due-diligence, identity-verification, and regulatory record-keeping requirements where applicable to an engagement
  • To prepare and submit company-related filings on a client's behalf with the Companies Office of Jamaica and Tax Administration Jamaica, including incorporation documents and the Beneficial Ownership Register (Form BOR-A)
  • To maintain records of business correspondence
  • To detect, prevent, and address technical issues, abuse, and security incidents
  • To comply with legal and regulatory obligations applicable to the Firm

The legal basis for processing is, depending on the circumstance, your consent (by submitting an inquiry), our legitimate interests in operating an advisory practice, or compliance with legal obligation.

Where you provide personal information about other individuals — for example, the directors, officers, shareholders, or beneficial owners of a company — you confirm that you are authorized to provide it and that those individuals are aware that their information will be processed as described in this Notice. Where consent is given, or a declaration acknowledged, electronically through our online forms or client portal, that electronic consent or acknowledgement is recorded and has the same validity as one provided in writing, consistent with Jamaica’s Electronic Transactions Act, 2006.

5. Status of Inquiries and Confidentiality

Important: Submission of an inquiry through this website, or other initial communication with the Firm, does not constitute or create a professional advisory relationship between you and Liguanea Advisory Group Limited. No duty of confidentiality, fiduciary obligation, or duty of care arises from such initial contact.

A professional advisory relationship, and the associated obligations of confidentiality and care, attach only upon the execution of a written engagement letter between you (or your organization) and Liguanea Advisory Group Limited.

For the protection of both parties, you are advised not to share confidential, proprietary, or sensitive information in initial communications. Such information should be exchanged only after an engagement letter or non-disclosure agreement has been put in place.

6. Third-Party Service Providers

To operate our website and communications infrastructure, we engage the following service providers, each of which may process personal information on our behalf:

  • Hostinger International Ltd. — web hosting services (servers located in the United States)
  • Web3Forms — contact form processing and submission delivery (United States)
  • Cloudflare, Inc. — content delivery, performance, security, and privacy-friendly cookieless website analytics (United States)
  • Microsoft Corporation — email and productivity services through Microsoft 365 (data centers in multiple jurisdictions)
  • Twilio Inc. — delivery of one-time access codes by text message (SMS), where a client chooses to receive codes that way (United States)
  • ZeroBounce — real-time verification that an email address is valid, at the point an inquiry or access request is submitted (United States)
  • Namecheap, Inc. — domain registration services (United States)

These providers are bound by their respective data processing terms and privacy commitments. We have selected providers that maintain industry-standard security practices and applicable international transfer safeguards. Each provider's own privacy notice describes their data handling in further detail.

7. International Data Transfers

Because several of our service providers are located outside Jamaica, personal information you provide may be transferred to and processed in the United States and other jurisdictions. We rely on standard contractual terms, applicable adequacy frameworks, and the legitimate interests basis for such transfers, and we select providers that maintain protections consistent with the standards set by the Jamaica Data Protection Act 2020 and, where applicable, the EU GDPR.

8. Data Retention

We retain personal information only as long as necessary for the purposes for which it was collected and to comply with our legal and professional obligations:

  • Inquiry submissions: retained for up to twenty-four (24) months from the date of last correspondence, unless an engagement results, in which case retention is governed by the engagement letter and applicable record-keeping obligations.
  • Engagement records: retained for the duration required by applicable professional, regulatory, and legal obligations, typically a minimum of seven (7) years following conclusion of the engagement.
  • Documents provided through the client portal: retained for the duration of the engagement and for a period of seven (7) years following its conclusion, in line with applicable professional, regulatory, and record-keeping obligations. Documents no longer required after that period are securely deleted.
  • Client-uploaded documents and the ability to remove them: a client may remove a document they have uploaded through the portal up until the point at which the Firm has received it. Once the Firm has accessed or downloaded an uploaded document, it forms part of the engagement record and can no longer be removed by the client directly; from that point its retention is governed by the periods described above, and any further removal is handled by the Firm in accordance with this notice and applicable record-keeping obligations.
  • Earlier versions of documents: where a document shared through the portal is replaced by an updated version, the earlier version is retained as part of the engagement record rather than overwritten, so that a complete and accurate history of the documents exchanged is preserved. Retained earlier versions are subject to the same retention and secure-deletion practices described above.
  • Technical logs: retained for shorter periods consistent with our providers' standard practices, typically 30 to 90 days.

Information no longer required is securely deleted or anonymized.

9. Information Security

We apply reasonable administrative, technical, and physical safeguards to protect personal information against unauthorized access, alteration, disclosure, or destruction. These measures include:

  • Encrypted transmission of website data using HTTPS with Strict Transport Security
  • Multi-factor authentication on administrative systems
  • Access limited to the Principal and authorized service providers on a need-to-know basis
  • Use of reputable service providers with their own security certifications and practices
  • Spam filtering on form submissions and network-level protection through our content delivery provider

For the secure client portal specifically, we apply the following additional measures:

  • Access is granted only after identity is confirmed through a one-time access code sent to the client's verified email address — or, at the client's choice, by text message to a mobile number the client provides; there are no standing passwords for client access
  • Each client can access only their own documents; client storage is segregated so that one client cannot view another client's materials
  • Uploaded and shared documents are stored outside the public area of the website and are never directly accessible by web address; every download is individually access-checked
  • Uploaded files are validated by type before they are accepted, and permitted file types are restricted
  • Administrative access to the portal requires two-factor authentication
  • Portal activity is recorded in an access log to support security monitoring and investigation

Our security practices follow recognized industry standards. One-time access codes are time-limited and expire after a short validity period, and authentication controls are designed in alignment with established guidance for digital identity and authentication, including the principles set out in the U.S. National Institute of Standards and Technology (NIST) Special Publication 800-63B. We apply these practices as a matter of good practice to support the protection of personal information; they supplement, and do not replace, our obligations under the Jamaica Data Protection Act 2020.

No system can guarantee absolute security; however, we work to maintain protections commensurate with the sensitivity of the information involved.

10. Your Rights

Under the Jamaica Data Protection Act 2020 and, where applicable, the EU GDPR, you have the following rights with respect to personal information we hold about you:

  • Access: the right to obtain confirmation of whether we hold your personal information and to receive a copy of that information
  • Correction: the right to request correction of inaccurate or incomplete information
  • Erasure: the right to request deletion of your information where there is no continuing lawful basis for its retention
  • Restriction: the right to request that we limit the processing of your information in certain circumstances
  • Objection: the right to object to processing based on legitimate interests
  • Portability: the right to receive your information in a structured, commonly used format, where technically feasible
  • Withdrawal of consent: where processing is based on consent, the right to withdraw that consent at any time

To exercise any of these rights, please contact us at the address in Section 11. We will respond within the timeframes required by applicable law, typically within thirty (30) days. We may need to verify your identity before acting on a request.

Please note that the right to erasure is not absolute. Where we have a continuing lawful basis or a professional, regulatory, or record-keeping obligation to retain information — for example, documents that form part of an active or concluded engagement record — we may be unable to delete it on request. As described in Section 8, a document a client uploads through the portal can be removed by the client until the Firm has received it, after which it forms part of the engagement record and is retained in accordance with this notice.

11. Contacting Us and Complaints

For any question, request, or concern regarding this Privacy Notice or our handling of your personal information, please contact:

Liguanea Advisory Group Limited
Attention: Privacy Officer
Email: [email protected]
Kingston, Jamaica

If you believe your data protection rights have not been adequately addressed, you have the right to lodge a complaint with the Office of the Information Commissioner of Jamaica, the supervisory authority responsible for enforcing the Jamaica Data Protection Act 2020.

12. Updates to This Notice

We may update this Privacy Notice from time to time to reflect changes in our practices, our service providers, or applicable law. The most current version will always be available at https://liguaneaadvisory.com/privacy/. Material changes will be communicated through prominent notice on this page. Continued use of the website or continued communication with the Firm after such updates constitutes acknowledgement of the revised notice.